Domain Verification and Application Registration

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Implementing OIDC authentication for the Jamf platform begins by verifying that you own your domain. To do this, you must add a specific DNS TXT record to your domain, which ensures only authorized organizations can create connections to your Jamf services.

Warning:

If this record is removed, your SSO configuration will stop working after a 14-day grace period.

After your domain is verified, you create an SSO connection in Jamf Account and link it to your organization's identity provider. You can then specify which Jamf services will use this connection. User accounts in the identity provider should be aligned to existing users in Jamf Pro to ensure successful mapping. After setup, all sign-ins will route through your identity provider, keeping access secure and tied to your organization.

The following diagram details this process in full: